First published: Mon Mar 28 2022(Updated: )
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Struxureware Data Center Expert | <=7.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22795 is a vulnerability related to Improper Neutralization of Special Elements used in an OS Command (OS Command Injection).
The severity of CVE-2021-22795 is critical with a CVSS score of 9.8.
The affected product is StruxureWare Data Center Expert (V7.8.1 and prior) from Schneider-electric.
CVE-2021-22795 allows for remote code execution when performed over the network by exploiting a command injection vulnerability.
To fix CVE-2021-22795, upgrade to a version of StruxureWare Data Center Expert that is higher than V7.8.1.